MetraFit Privacy Policy
Last updated 6 September 2026
The short version. MetraFit is a food and weight diary. Everything you log is stored on your phone. It only leaves your device for things you switch on yourself: syncing to an account, searching the food database, scanning a barcode, importing a recipe, or estimating a meal from a photo.
We do not sell your data, we do not run ads, and there is no analytics or tracking SDK in the app.
Who this is from
MetraFit ("we", "us") operates this app. If you have a question about this policy or about your data, write to support@metrafit.app.
What stays on your device
Your diary lives in local storage on your phone: food and exercise entries, weights, custom foods, saved meals, recipes, your reminder times, and your profile (name, age, sex, height, weight, activity level, and calorie and macro goals).
Meal photos stay here too. When you log a meal from a photo, the picture is saved in the app's own storage on your device so the diary can show it back to you. It is not uploaded to us, not included in cloud sync, and not part of a backup file. Deleting the entry, or removing the photo from Me → Meal photos, deletes the file. Uninstalling the app deletes all of them.
You can use MetraFit entirely this way. Choosing Continue without an account on the login screen means none of the above ever reaches us.
What leaves your device, and when
| When | What is sent | Who receives it |
|---|---|---|
| You create an account or log in | Your email address and password. Passwords are hashed by our authentication provider; we never see or store the plain text. | Supabase (database and authentication, hosted in the United States, region us-east-1) |
| Your diary syncs | Your whole diary as a single record — every entry, your weight history, and your profile — stored against your account. | Supabase |
| You search for a food or scan a barcode | The search text or the barcode number. No account identifier, email, or diary content is attached. | Open Food Facts, an open food database |
| You import a recipe from a link | Your phone fetches the page you pasted, directly. That website sees the request and your IP address, as it would in any browser. Nothing is routed through us. | The recipe website you chose |
| You log a meal from a photo | The photo and any note you typed with it, sent to our server function, which passes it to Anthropic's Claude API for an estimate. We do not keep the image after the estimate is returned, and it is not used to train models. | Supabase Edge Functions, then Anthropic |
| You subscribe, or restore a purchase | Your subscription status, linked to your account identifier. Payment is taken by Apple, Google, or — for a purchase made on our website — Paddle, which is the seller of record for that sale. We never receive your card details in any case. | Paddle for website purchases; RevenueCat with Apple or Google for in-app purchases |
Health data
What you eat and what you weigh is health information, and we treat it that way. It is used for one purpose: showing you your own diary and totals on the devices you have logged in on. It is never used for advertising, never sold, and never shared with anyone beyond the providers listed above, each of which processes it only to run the service.
What we do not do
- No advertising, and no advertising identifiers.
- No third-party analytics, crash-reporting, or attribution SDKs.
- No selling or sharing of personal information, in any sense that applies under GDPR, the CCPA, or comparable law.
- No profiling and no automated decisions that produce legal effects.
Why we are allowed to hold it (GDPR)
Where the UK or EU GDPR applies, we rely on performance of a contract to run your account, sync, and subscription, and on your explicit consent for health data, which you give by choosing to create an account and sync. You may withdraw that consent at any time by deleting your account, which is a two-tap action inside the app.
How long we keep it
Your synced diary is kept for as long as your account exists. Delete the account and both the account and the synced copy are removed immediately; backups age out within 30 days. The copy on your own phone is deliberately left alone, so deleting an account is never an accidental way to lose your own history — Erase everything on this device on the Me tab is the separate local action.
Your rights, and how to use them
- Delete your account and synced data: Me → Sync across devices → Danger zone → Delete account. No email to us required.
- Export your data: Me → Export a backup writes a full JSON file you can keep or move to another device.
- Access, correction, portability, objection, or a complaint: write to support@metrafit.app and we will respond within 30 days. If you are in the UK or EU you may also complain to your national data protection authority.
Children
MetraFit is not intended for children. You must be 16 or older to create an account, and the app is rated accordingly on both stores. We do not knowingly collect data from anyone younger; if you believe a child has created an account, write to us and we will delete it.
International transfers
Our providers are based in the United States, so if you use MetraFit from the UK or EU your data is transferred there. Those transfers rely on the Standard Contractual Clauses in our agreements with each provider.
Security
All traffic is encrypted in transit with HTTPS. Synced diaries are protected by row-level security in the database, so an account can only ever read and write its own row. No system is perfect, and we do not claim otherwise.
Changes
If this policy changes materially we will update the date at the top and, for changes that affect what we do with your data, tell you in the app before the change takes effect.
Not medical advice
MetraFit is a logging and wellness tool. It does not diagnose, treat, cure, or prevent any condition, and its calorie and macro figures are estimates. Talk to a qualified professional before making significant changes to how you eat.